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(57) Abstract 

To evaluate the randomness of an S-box, the indices of strength against the high-order differential attack method, interpolation attack 
method, division attack method, and differential linear attack method and the necessary conditions under which the indices have resistances 
to decoding methods are determined. Whether or not each of function candidates meets part or all of the conditions is checked, and 
candidates which meet the part or all of the conditions are selected, as necessary. For each selected candidate, the resistance to at least either 
the differential decoding method or the linear decoding method is evaluated, and function candidates having strong resistances to at least one 
of them can be selected, as necessary. 
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^^tfi:^x\^^^oX\i^tim^^t>-MX'h^=7:yyd>.mwm-^^'^-t^s-hoy. 
^(Dxmtimm^mt vx^-r^ROM^^ix^mf^-t^^ticx ^ ^^^^^pm 

#^oS-box }:ij-t^6^Ji^^Ji: LTDESCData Encryption Standard) XWiF^^tlXU 
^(7)^^^4-^^l+^fe{-ov^TW^$i^T#fc:o s-box ^Itj^Jc-rsi^lci, 
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ife Te. Biham, A.Shamir: "Differential Cryptanalysis of DES-like Cryptosyst 
ems, " Journal of Cryptology, Vol. 4, No. 1, pp. 3-72J X\ MiMMBWij^^^CMi I'M. 
Matsui: "Linear Cryptanalysis Method for DBS Cipher," Advances in Cryptol 
ogy-EUROCRYPT' 93 (Lecture Notes in Computer Science 765), pp. 386-397, Spri 
nger-Verlag, 1994J T'ft^^n, #< (Dy-'u y ^ ^nh(Dmnm^ ^ ^ 

^\^x'%.\^^hii>^i^^f\.^^b\^f^-^it.. ^^x. ^th(b(Dmw.mz.n\^xm\^ 

TM. Matsui, "New Structure of Block Ciphers with Provable Security agai 
nst Differential and Linear Cryptanalysis," D. Gollmann, editor, Fast Sof 
tware Encryption, Third International Workshop, Cambridge, UK, February 1 
996, Proceedings, Vol. 1039 of Lecture Notes in Computer Science, pp. 205 
-218, Spri nger-Verlag, Berlin, Heidelberg, New York, 1996J X^^^flf^o 

:Lf^h(D^mv^A^■^^^'^\^lf^fl^fh(Df^mm\^n-t^m\^t^^^^t■A^^^f\.x 

-XM. TT. Jakobsen, L. R. Knudsen: "The Interpolation Attack 
on Block Cipher," Fast Software Encryption Workshop (FSE4) (Lecture Notes i 
n Computer Science 1267), pp. 28-40, Springer Verlag, 1997J {dioV^T^ ^j^M 

mm:^mmmmmcn-r^mi^(D ^ s w^-^x . M^^^^^m^mm^m^^ x^x 

^^^M^^'T^^^'^W^^mU^K-hX^ rc.Harpes, J.L.Massey: "Partitio 
ning Cryptanalysis," Fast Software Encryption Workshop (FSE4) (Lecture Note 
s in Computer Scinece 1267), pp. 13-27, Springer Verlag, 1997J l^doV ^-Clt?f^ 
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nvx^±Kmm^^h^ ^ t ^mE-r^i&mnm^.^-.xit.mtLi^x\^^fj:\^\ m-h. 
Ht-^;^^ znh (D^m\^i^\^x^^xh ^fc^K^^i^^j^ m^. V 5s-box 

L;i^L. S-box ^mf]-t^±X\ ^tih(D:^mmi^Mi^Xi,-\'i^fj:^&^i^-^i: 
0 fc-rs r h ttfiS^c^iiST-feSo s-box Xz-y^-f-^ z.f\.h(D^m\t.X)^f)mm:.\^ 

?^^t)(^^fi^ff-r-5:ii:-t?fe'2)o t*feoT. J§:i^tc^-rs S-box (^M^ttt^Mi-^ r 
«S-box (Oy^-y^^MlL^W^-t^ Z i:-efcSo 

r(D^PJ(^-g6^fl. _bfEcD#5fi:llife}c*]-L. ^(^5fc»&}v:^-rsgs^ 

t^(D7^m(Dm4^i§.^^i^x^(Dm^NU-f)^i^^^^i^^^M^w^^^m^M-t^mi 
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4 

b (S(x)+S(x+Ax)) tttl;^C>-^>c.i5'^itry t(DpHmi)^ 1 X-h^ (DmWL^i^^Xm. 

r <Dmm\^ ct ^ ^ :^yj^mwi:^j^mmRi^^si^:f^m\^^^^xi-i. i-^mmmcomti: 

1 3(^fS'lt$ix/c#av^'-^;6SScttl$n. M^^^icWtttM^Ha . »0^»cfe 
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5 

4g t:-^n-^^;n.w=tttf¥i5> mmnm^j:t't)^ti:^n^. ^(o^^^^^ht-^^. »tt 

o/c:fc(Digi>S^f4^^ai-<So i^T-Cfln, m^^E<75g^ici S-box (^^^5^' 

feT'f*. s-box (D2o(DA;^(DM53- ix:f:m^m.) icM-r^w,ti<Dm'^ imtimi^ 

s-box (7)A;'j^x, 2^(DXtl(Dm^i^^ Ax . ^(D 2 0(^A;^{->*/^^-r ^ 2 o 
(^ttJ;'j(^Mr9-ffi^Ay . S-box (DMiSc^S. A;^x};i>Pj-f5S-box ©!li;^y^y=S 
(x)^-f-§i!. ft:t<7)A:^SI^1fiAx iiM(Dliitim^mAy izMVX. ^X<D 

S(x)+S(x+ Ax) = Ay (1) 

^mfz.-r7^(Dmm^ 5s(Ax, Ay) t-r^. mb. "+" fit' 5/ hm(Dwm 

6^fmSI?n (XOR) "C^^^HSo rx. Lai, J.LMassey, and S. Murphy. "Markov 

Ciphers and Differential Cryptanalysis. " In D. W. Davies, editor, Advances 
in Crypto logy-EUROCRYPT '91, Volume 547 of Lecture Notes in Computer Sci 

ence, pp. 17-38. Springer-Verlag, Berlin, Heidelberg, New York, 1991J X 
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6 

-^X.btl/cAx iAy ^^^^-5 X ©f@^6 s(Ax, Ay) « 

6 s(Ax, Ay) = # {xeGF(2)" | S(x) +S(x+ Ax) = Ay} (2) 

<OJ:9^c:^^$i^6o mt. # {x I ^#^} «^#^^-m-t-x coMir-TSo A 
;^^57-{iit LTO^|^<^T(Dn hr^ — ^ Ax t LT^-r(7)m 
t^>;/ — Ay {C^LT.^(2) J;'96s(Ax, Ay) ^ffm-T ^ ^ <b 5o 
:icD5-bft^>±#v^fit^t^ Ax <!:Ay (D%^^^ib>m'M%mmz.ion ^mMM.t 
^^Sfcfe. 6 s(Ax, Ay) (^ft±ffi;6>/h^v^{5^'^^j?i?^j£{::xti-§«;0S:^#v^ 

As =raax6s(Ax, Ay) (3) 
-e^ $ n -5 As /js $ V N r i m'M^mm i^^f b T Wtt ^ ^> o 

/^§o ^(3) fiAx =^0. Ay (D^M-B-iirOctJii^A^/^cD 6 s ^31t>\ 

As (Drntir^-t^m-r. 

s-box (D,»^j|?Sgfe}^^i-^iiftt^^i-m#i: LT»^J{cllit^^^«L.^<^ 
m.'^^nw^x\%. s-box (^A;'jfit^rm;'j^it(Dt'>^ bm{4:T'<D^S'7)ll?f^?p (S^ftU 

S-box (DKti^yi. T^ti'^-^^m.^Tyi . tli;'^-^ {fi^ Ty ^-rSi:. feSA 

;^-^;^^'(iirx i±i;^-^;^i:'^itry {c^lt. 2fe^(4) 

As (Fx, ry) 

= I 2X# {x eGF(2)" | x • rx=S(x) • ry}-2" | (4) 
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7 

" 1 " i:imtir^ X ^(D}fy hm(D^^^^^t LT. ^tihmu^ t ^ ^ t ^^t> 

•to W'h. X- rx=£xi (Efirx ^(DMi hi> "1" (D^-^U) 'fB.Lx=(xn- 
i,"-,xo) t-r^o y ry(DMMhmm'(:h^o ^oX. ^(4) tt-^;tbn/c-7^ 
i^-ffitDm (rx, ry) {;i^L. n Ify h(D^X<DAtl-x. (2"'(@fo6) (D^-h. x- 

rx=s(x) • ry ^mSit^^(Dmm:(D2m^^h2''^mw\^xmcm(7^mmu^m 

h7=-^ry (D±X(Dmi^M\^x^'tn^'ti^(4) <J:«9 As(rx, ry)^fi-^i-s^ 
<i!;0s-ets„ rcD9-^is(rx, ^y);^»i^ftti±#v^^it^^ 5 rx try (Dm.:^mjf^M 

As = maxXsCTx, Ty) (5) 

x^:^n^'mmm^mAs ^^/b:^\^^^k^mmMnm^n\^xm\^^-h-:>±i^ 

^(5) itTx , ry^O(Di^X(Dm.^i^^(D'=p:b^hXs(rx, ry)(DM±W.^mx^. 

As t-r^:it^m-ro 
s-box (Dm^m^T^^mm^mr^m^^^-rmmt vxmmm^A^mmm^^ 

mmmi^^mmtn.w^-^itm^cD^mtiiti^Atucmi.xMmm^'^t^t. 

yj =xo+Xi X3+X0X2X3+. . . +xiX4XsX6"-xn (6) 
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8 

S-box S : GF(2)"-^GF(2)" ; xh->S(x) 

y= S(x), (7a) 
x= (xn-i, Xn-2, xo)e GF(2)", (7b) 
y= (ym-i, ym-2, yo)G OF (2)" (7c) 

Si :GF(2)" ^GF(2) ; x h-» S i (x) (8) 
^^*L, mWM^X\:imi-^y—/l^mmi (O^i^m-D <D^m^ degxSi<b 
-rSo i^TOJ:5l- degxSi (0^ i ^m-1) o^/Hit^degx S ::tL;6^S5Pi 

degxS= min (degxSi) (9) 
min i ^m-l^^#i:-rao 

i«Ptll5^5i:^(C^bT^^-efe^/c*{::S-box ;iS^fc-f--<ti£i^^^f^«.degx S;5S 

6) degx S(Dft;/^{^^^^n-l-efe2>::<b^s^^i^Tv^6o 

s-box (Dmm^mm^M-r^Mm^Tjk-rmmt uxw^^^mm^^mv.t<D 

V^T(DGF(q) _h#Ii^fk(x) ^fflV^TMx.(m5^ 
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9 

y = f k (x) =c,-ix"'''+c<,-2x'''^+. . . +Cjx^+. . . +Cix'+cox'' (10) 
:5: t ^ tc^f -59^^:5: com (xi, yO (i=l, . . . , c) i'^M-^htitiit. 

#iS5(:fk(x) ^;l^*nsISi^;55#v^^^^^ GF(q) ±^m^mmy^u) ^m^^tc 

S-box COGF(q) ±#IS^^mtC:-a*tL63SW^^>^c?V^<Jr.Bt-^^^<DGF(q) Jb# 
^^^^f;i'a-*tL5Iiic;^S^J'^7^cf< "Ttl14;55*>^o ^^^5Ay. S-box CDGF(q) 

i:(iGF(q) ±S'm^mm^^^n^mm^^\'^:it:dmm^mmi^M-r^Mf^^ 

i^-Df^i^(Di{^-m^i^tti:^o s-box (DM^ScDGF(q) ii^II^^^til'a ^tb^J^^ 

srcoeffaS tL.^n^GF(q) ji^m^^^^m-r^mm^m(Di^mmmt-r 

-<<^<(DGP(q) ±^m^^m^ML^X^(Dm^ coeff<,S ^ff^ L. -enf^^e/^/h 

S-box (D^tm^tiicxt-rawtt^^-rji^^ uT5>fiJ5icig*t«^^«b.-?-c^ 

f$:(DlifSci;io7^^(f5w^75sr'#5o r^ej ^^cDJi^ ij ^ UTfi. xm rc. H 

arpes, J. L. Massey : "Partitioning Cryptanalysis, " Fast Software Encryption 
Workshop (FSE4) (Lecture Notes in Computer Science 1267), pp. 13-27, Spri 
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nger Verlag, 1997J "Cfipeak imbalance <h squared Euclidean imbalance i)^MtL' 

tioning cryptanalysis of DES, 1998^B^-^i: If #ir=3r ^ y 7" v- -^^^i 
M (SCIS' 98-2. 2. A) J }^*5V^T. DES Bf^iDS-box (DAtSit}M^i^1^\^Xm.M^tl 

^m'o^^mi^x. Bt-^^#:(Z)J^f^^^c^?bLTv^-5r s-box (DAtattm^ 

s-box (D^yKtim-^^u6^mL±^^m^^Fo, f., ... . F.-^.^mtim^^ 
v^^mvfcu^^m^^Go, Gu .... Gv-, t-r^o ^U6^m^\^^^n^mmmi-i 
ikT^Lv^^i-^o Atiy^^^m-^M^fDm^ {0.1,.... u-i} iz^i^-r^^mwuf 
^xtKD^mmm. iiitiy^^^m^(DmK.^{o.i,...,v-i} ic^m-t^mmg 

F= {Fo, Fi, Fu-i} , 



-e#;ie3ti^o ^(11) <^*iai;i*5it^i(g(s(x)) | F(x)-i)^i(v)-c^-rt . m 

;^Sffia7ji(D rji;^Ij -efci9. C.Harpes ^<DffJlB:5:i^{- rcDtg^tUTpe 
ak imbalance^i^ffl-rS^'^fl^^ 



-e^$tL-5o '^fc. squared Euclidean imbalance ^t^Mt i.X^mi-^m'^l'illk 




t-r^t. s-box 05^Sim(F, G)Oii"9Is(F, ofm^di) 



u-1 



Is(F, G) = ZI(g(S(x)) I F(x) = i) (11) 




(12) 



iE(v)=^i:(p[v=j]-i)' 



(13) 
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11 

-C^^n5oPCV=j]ti*5-5 i (i=0, ...,u-l) ^B(DAtlifJ^~y'F,(D±AtlxlcM 
Jt^'i-^^m:^! y 7!)'^tiitl i//i---7°Gi (j=0, .... v-1) --'J*«i-S L.'ttl^^th 

ntt'^Vl^— :^Gj--(D'JtM?fe^(*kj/Ki-efe5o 5t(12)(7)peak imbalance Ip(V){ift 
i^mmm^(D^i^m^^^h(Dmr) ^lEm.^tl.fcm^m\^. ^(13)(7:>Euclidean imb 
alance Ie(V) f^'jSMW^O¥i^;0^ ^ (DM "9 <D 2 ^^O^IE^^b Lfcfit^* LTl/ 
rcDtg^IpXfilE^^(ll){CigfflLT#S^Sim(F, G)(^oV^T'(l'5 Is(F, G) ^ 

ofc^6<Die^^^^{^<^7fc5o tJ^o-r. I Is(F,G)-l/2 I (Dfji;iST:-#Sfc(t/J^^ < T^cf^ 

s-box m^^m^o 

S-box OA;^^x. Atim^m^^^ ^ ai;^-7^^{fi^ry i:-r^^. 
^s(Ax, ry) = |2# {xeGF(2)" | [S(x)+S(x+Ax)] • ry = l}-2"| 

(14) 

-Cf+^^n-SJi^e s(Ax, ry)C0 5^.^'C(DAx, Ty (Dm^'^t>'^(D ^ ■tb(D7^^ 

5s = max ^sC^'^'W (15) 
Ax5tO,ry?tO 



wo 99/63706 



• 



PCT/JP99/02924 



12 

S : GF(2)"-^GF(2)" : x^'' in GF(2") (16a) 

S : GF(2)"->GF(2)" : x -» x"''^' in GF(2") (16b) 

t:i^X^ XW^ Tt. Jakobsen, L. R. Knudsen: "The Interpolation Attack on B 
lock Cipher, " Fast Software Encryption Workshop (FSE4) (Lecture Notes in 
Computer Science 1267) , pp. 28-40, Springer Verlag , 1997J Xmifhnx\^^ 

m^h-^mwu^mAyxs-hox t vxmmi..t(Di-tmmm^^^^<f:^^^^M(D^tm. 



m 
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J^J^T. ^2(Dm..'^j:iX^mMmx\i. S-box tl^XS \fy h AI±J;'^<DS-box (Dm 

^-r, s-box 2 0 ^tt^K-rsf^ffiMm.^ bT. -B^Jx-f^m 2 tc^i- J: 5 {::Ba^P(x. 
e) ^±f^i-^ P r*m§l5 2 1 mmPU, e) .J: <t^«it^m{Cli-^ ^^A(y. a. b) 

S :GF(2)" -*GF(2)' ; x A((P(x, e)) , a, b) 

mb 

P(x,e)=x^ in GF(2') (17) 
A(y,a,b)= ay + b(mod 2^) (18) 

b-CV^:5;6S^ i^P^^^^JflS. mMW:^^^. ^m^m. ^fiJ5Jf«^^=f ^l;i>Pi-bTM^ 

ii^mm.^^. v^-ri^(7)5l^l^^c^bTt>iif'l4S:^b-CV^Jfev^c 

r CT'}^. iJ' a , b, etiOJM_b255 (gn-^2"-l) Je>lTcOftS<7) g 

gfiit:^^*)'5o ^ a, b(7:)^>5 ^-i^fi^^SJe^iSJe^Tt- 

PS^b. ^ a , b {^^8 \f^y VX^^t^^(r) o "b"!" (X{*"0'') 75^ 3 t'^/ h^i 
±5 \fy V^J^TXh^. Ml:iS-box r ^ . Wt^MU^. WmUW^i. 
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14 

fcir^^t^^:^^^tm^. ^-^y?^—^ a, b, e ^^^)iA^-ev^<„ 

0m:L(Dmi^mhnfj:\^\ s-box (Dm^t-r^mm(Dmv^:^ia'i^^mr^h^. * 

T.'ryZfS 1 \ l -ei^i6^(17), (18) (c:*5{t^^-^°^^-^a, b, e (DM. 

h(b) ^3i^A±5iei.Tt;iPS^-t--5o 

e;0^2'-l=255.i:^v^^c^ ( (e, 255)=li:*-r) Tfe^Bt. Bi^S (t^^Mtc;^^^ 

>^^ix-7°S3 : e(D^N^ Vi/M^Wh(e) ( 2 m^m^CO e ^ (D" 1" (Dm^X^^'O . 
'e^!j;t{ie=11101011T'fett«*Wh(e)=6 ) <b M^P (^^"^/^M^^^-CcD^^deg, P 

egx S<7)^i4^^Mfct-fc^. r^-CfidegxP. o-^«9 ei7)/^^ :/i/S^Wh(e) (7)3 
fiS^ft^fit-efoS 7 {^IT'i 6 t> (7). Hp-^e=127, 191,223,239,251, 253,254 ^JltR-TSo 

^^5/:7'S5 : :^y'y^X-mmi!)>^J:^'tm^^nfcm^. Wh(e)^Wh(e)-l^^ 
^^ix::/s 6 : >^7"5/:/s 3 (DMST-aofd^M(?)M^S {z:ov^T. ^(3) xm 

m^n^m^Mmmm^s ^^^^^^^tzmmmAn OT<t^.e^t(^^ji*R-r6„ ^ 

n Sr-a $ Tie V ^ t> (D ^ 1^ < o 
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(a, b) = (97, 97) , (97,225), (225,97), (225.225) 
e = 127, 191, 223, 239, 247, 251, 253, 254 

^i^'^\z.x^i^mmmsK-D\^^x. ^m^mmms(F,G) iisXf, 0-1/2 

><>7":y:7°S 1 8 i^^.x^'^^S 1 5 (D^ST'aofc±tB/^°^ 7^ — ^ (^^■C(DMa^'g' 
<,S (/c/cUq=2') ;5SSMc<,R U±t^£^h(D^mn\^. ^ixi^i^^l^^i-^o 
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il>ic<,d ^nW-r^ (^W=^<4>^i^^) r ttci DSWIr^ML. y^y'^yZfS 
1 9 izm ^ . MS^^ 19 3i-t-„ 

S 2 1 \Z.m «9 . ^S^M t) 5M-t-o 

(a. b) = (97, 97) , (97. 225) , (225, 97) . (225, 225) 
e = 127, 191, 223, 239, 247, 251, 253, 254 

v>(D-c% s-box tLx t^(Dmwc^mAyx-^xi\ 

s-box (Dwrnti^x. xitm^^j^i^i^^^Xs ^wmmm(Dmmw.AR, ar, 
hr, cqr, cpr fi, -D^'o^m(D^m\zMvm>k 
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mtLirh(D^m^i^x-h^\'\ 

mn-^'^miy > A Mi^^^ife;^?* ^ 3 1° ^ — ^ -e^M-r ^^T^n^^-^i^tu 

Tf5^^#:(Ci^ fetB^ b-C*3 # . ^ (^IB^I«#:(D :7° u i:^' ^ ^ =t f ^ - T'S! 
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mm^'h-^mmim&^^io'it^^hms^ t x\ s-box h ^ 7^ kt (mf^tii-f 
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(D-<^mm(Dmm^^h^^^^^rnTW±(D^m^^my^xiiitiy ^y=fUx) tm^ 
LT. ^(D:^wc-A^:kxh^i^}fmm^mm^M-t^Mm 

L (S(x)+S(x+Ax)) ^tb;'j(D-7;^i^ffiry t(Dp^m-b^ 1 -e$>S xCD«^^J6-C^ 

m(DAt)U^M^ {Fo, Fi, .... Fu-i } t vm(Diiitl^'^M'^ {Go, G,, .... 
Gv-, } (vl^fijL. #^SiJ*f(F,.Gj)(i=0,...,u-l;j=0, l....,v-l)lC0V>TA;^lf|5 
^^-S-^Fi (75^A;^ X i^MJt-t^^tatl y >^)S^^^^^tLCDm;'J^H55>*'^Gi (j=0, . . . . v 

^;lSov^-c^flm(F,G) o^J^^isOc^m^lsCF.G) 

^ s(Ax, ry)= I 2X#{xeGF(2)" | (S(x)+S(x+ Ax)) • ry=l}-2" | 
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=^ A y ^m-r X (Dmm^^ ^ x m^mnm (c^-r^ m^^wm-r ^ m^mmmm^ 
4 . If 3 um(Dy><^^j^m^mmmi^i^\'^x. ^mmmmmmmmwm^i-i. 

ry=o ^l^<:^T(7:)-^^^«©m(rx, ry) iz.i(i]^7k^ 

A s(rx, ry) = I 2X # {xeGF(2)" | x • rx=S(x) • ry} -2" I 
As= max XsiTx, Fy) 

Ax=0 ^|^< ^-C<D^5>^l:<^*l(Ax, Ay) (Cl^L^^ 
6 s(Ax, Ay) = # {xeGF(2)" | S(x)+S(x+Ax) = Ay} 

As= max 6s(Ax, Ay) 
7. ft;^<3S6f5^(D^>'^i.M^^fifei^S(-^3V^-C. 
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mm(Dmm:^^hts:^:^^tiTW±(D^m^^m\^^Xliitl y ^y=fk (x) i^JELT.± 

±mmmmm(D±x(DAtit^h.hKn}tir^m:fj^^n'en(DU^^m-^i^^7^ 

±mi^mmm(ydK-^^^X±X(DAtim^Ax tiHti-^^^^iW-ry (D^xcom. 

icML. (s(x)+s(x+Ax)) tmti(D-^:^^m.rY t<D[^m^^ix^^K(Dm^^^ 
i^xmi^mwmmmi^M-r^m\^^wm-r^m:^^mmmumwm^^ t . 

9. mm(DAtiitimm(D^>yM,^^mm-t^^mx^^ . 

(b) ifii-r-<#Klics(x)}cov^TA:^M^Ax <bai;':>-v;;<^i^'fitry (D^rom 

\Z.n\. (S(x)+S(x+Ax)) ^m;'7(^-^^i5'ffiry ^(DF^^^^S i "Cfc 6 x 
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10. li*Il9^D^^^^A+4rT^;^i&^-jov^T. 

^s(Ax, ry) = |2X# {xeGF(2)" | (S(x)+S(x+ Ax)) • ry = l}-2"| 

^^^^'ivumcDAM^M^ {Fo, Fi, Fu-.} tYm<Dlii:bU^j^m^ {Go. 
Gi, Gv-.} (C^fiJL. #5>fJ^(Fi.Gj) (i=0, ...,u-l;j=0, l.-.-.v-Dtdo 

v>-CA;^;lf|5i9-m-^Fi (7)^A;^j x izMlt-T^^mti y ;6^^^x^^ix(Dffl;t;fl5:9-*-^Gi 

(j=o. . . . . v-i) -^mm-r^w^^i^.^xcD^^mi^iF.G) (Dmmmm(Dmy) (Dm 
;^is(F,G) ^i^i^^^(Dmm\^M-^^^x^m^mmKMi-^wiii^wisai-^^'Ty 

(Ax, Ay)lC^LS(x)+S(x+Ax) = Ay^'^-rxOpm^^H^'n*fe> 9 

(f) ±|^M#:S(x)^^ov^r^^7)A;'Jx <b^(D-x';5!LiJ'jjtr x (DF^^;dS^ 
S(x) ^-tcD-^^^i^^lSr y ^(Drt3MlC^L< T^eS x<7:)«^*it)T.»^j|?^fe}«l^ 
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1 2. fibril 1 (D 9 ^ J^mfi]Sa:^mciS\^ -^X. ±tiAtl:>^(D\f^y hm^n tir 

±mmi^Mn'i^wim^m^m:^y' y-^ie) ax=o ^m<^x<Dmi7^m(Dm 

(Ax. Ay) izni.'tM^ridi^ 

6 s(Ax, Ay) = # {xeGF(2)" | S(x)+S(x+Ax) = Ay} 
As= max 6s(Ax, Ay) 

^t. ry=o ^^.<±X(D%a.(D'^:^^mrx, ry) izni^i^^ 

XsiVx, ry)= I 2X # {xeGF(2)" | x • rx=S(x) • ry}-2" | 
As= max >ls(rx, Fy) 

(c-1) ±mmmmmi(D^iiit}\^^^y h^A:hif^y hi^Mir^zf—ji^^^^xmm 
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(c-2) ^mmmm(x)iz-D\y^xAtim^Ax tmti-^p^^mry (D±x(Dm(A 

X, ry) tc>pi-b-?-ix-ens(x)+s(x+Ax) itli;^I(7)-7^^5''^^t^y ^ oi^^;^^ i r-fes 

(c-3) ^mmm^(D^x(DAti t^tih {cm-r 5 as;^ ^^ti.^'ncD^^)-*'^ 
(c-4) mmmmi^nv. m^^^m^vx^^Atit *mpx}ip(7)-<#^^ 

(D^mt^hts:^:ffuTi^±cD^T^^^m\^^Xiiitly^y=fAx) -^^^LT. _btB# 

y) ^\^^mmmm^m\^xm^m^'r6mm^mMmwmi>!iim:^y^ ^yy^^ 

0^^.<Ati^S^Ax t 0^m<mti-^:^^m.ry (D±x<D%m:i-D\^^X^^ 
I s(Ax, ry)= I 2X # {xeGF(2)" | (S(x)+S(x+Ax)) • ry=l}-2" | 

^^n^num(DAtiM^M^ {Fo. F,, .... Fu-i } t V mcDiati^^M^ {g 

0, Ga Gv-. } (C^fiJL. ^5^fiJ*i-(Fi,G])(i=0, ...,u-l;j=0, l,....v-l)lc: 

i (j=o. . . . , v-1) ^mmi-^m^<D 5 ■^©s^m^**?). ^-c<d^sij*j-ic:ov>-co 
^Tos:'c1l^{cs-^v^T^f'J>pf(F,G) (D^m^M'o (Dmmi s(F,G) ^^tby^^m^ 

1 5. it^iciii sxfii 4(D^>^■Aii^^^;^^^-*5v^T. 
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(c-5) f^MM^S(x){COV^T. Ax=0 ^[^<^-CcDm(Ax, Ay) {c:>Pj-bS(x)+S(x 
+ Ax) = Ay^Mi" X ^nb<7) 5 ■^(7):^^'fitt:i J; 19 M^^jP^SS 

(c-6) #^^ffiM^^-ov^T-^c^)A;t»x t-^(D-7;^i!^^a:rx (DF^»:d^ M^tti;^^ 

ry) ic-D\,^xjk^. ^n^hicm^i^^xmnmrnm^n-r^m^^nmi^. mmr^^ 
1 7. ft^iii ^(D^iy^j>^wmL^i^-)jmz.^\^x. ±.^W:^nwmmmm^m 

y^y^y-lTic-S) (i. ry=0 ^|^< ^T^M^^jitf^mC Ax, Ay) (d^LtSJc^ 
6 s(Ax. Ay) = # {xeGF(2)" | S(x)+S(x+ Ax) = Ay} 

As= max 6 s (Ax, Ay) 



• 
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;Ls(rx, ry)= I 2X # {xeGF(2)" | x • rx=S(x) • ry}-2" | 
As= max Xs(rx, Fy) 

^yzf^^tio 

1 9. tf*iii 3, 1 4 32.fi 1 5£DV^-fi^;6^c^^>-yA||^^fc^;^^fe^c:^3V^-c. Ji 

(b) ±tBIIIW^S(7)ri^m^f2lt#^l3:|5'lt-r^MS^7^ y':ft^ 
(c-l) ±Mm^mWL(O^Vditi\^ y V^At}^'y hfcM-f^:/— 



wo 99/63706 



# 

PCT/JP99/02924 



27 

(c-2) #{^^MmS(x)(CoVN-CA;'jM^Ax t\^ti-^>^^m.Ty (D^T(^m(A 
X, ry) l:i^b^n^*tLS(x)+S(x+Ax) tmtKD-^ ::^^m.ry t (Dp^^i^^ 1 ^ 

(c-4) lik^ia^LTx^A;^c!r ^ifi:p Xfip 0-<t^{® 

(D^^;6^^^^5:*fnT«^±c^#^^^fflV^Tai;^y ^y=fk(x) .b^^UT,_hlE# 

2 1. mM^2 0(DmmmwK^\'^x. 

I s(Ax, ry)= I 2X# {xeGF(2)" | (S(x)+S(x+Ax)) • ry=l}-2" | 

^^fl^f\nm(DXtiW:i^M'k {Fo. P., .... Fu-. } t v m(D\i^tiU^m^ {G 
o, G,, Gv-. } t^5>*'Jb. #^«'m(Fi.Gj)(i=0,...,u-l;j=0. l....,v-l)l;i 

ov^T A;^gP5^m'a'F i (D±Xti X ic^^j^^-r^^m;': y ;6S^n^'tb(7)|±j;^^:«-S-^G 
j (j=0, . . . , v-l) --'j§m-r^?ft*(D9-^<^ft^#:^*^> ^T<D5^S^m{^OV^T(D 
^TOft^'fltlcS-^'V^-C^^SiJ^CF.G) (7)|it9(Dm«Is(F,G) ^Sr**!). 5>«'J^^C^^^^- 
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2 3. fS3it3S2 oxfi2 1 (Dmmmm^^^^x. -i^n^i^^T(D{i^ti: 

(c-5) {^MM^S(x){COVNT, Ax=0 ^m<^X(Dm.(Ax, Ay) l;i>Pl- LS(x)+S(x 
+ Ax) = Ay^^i-x (D-(@^^^n^'n**!). 9 ■^<^*:'cMi-<t m^Mm 

(c-6) #{^MIB^(;iov>-r^cDA;^x i:^(D-^;^i?Mrx ga^i±i;fj|it 
S(x) t^cD-r>!.i:7^ry i:CD|^jMi^L< ti:^±X(Dx(DmWc^^X(Dm(D(rx, 

2 4. ff^iI2 3 0lS^^^*:}c:*5V^T. JilEM5^jii?»c&i»ttfFM^a;=^7^ 5^ :/(c- 

5) (1. Ax=0 ^^<^r<DM:9-ffi(^m(Ax, Ay) tC^biSfe^ 
6 s(Ax, Ay) = # {xeGF(2)" | S(x)+S(x+Ax) = Ay} 
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As= max 6 s (Ax, Ay) 

ffi(rx, ry) {cML^s^ 

IsiVx, ry)= I 2X # {xGGF(2)" | x • rx = S(x) • Ty} -2" | 

A s = max 1 s ( r x, F y) 

2 5. ft5itli2 3X^*2 4(DS^^IS^^C*5V^T. 
±fS;^ X :y ^(c-5) ^ t^c^ fc^-^fi:. JilEll 5 S^J^^H 5 (^filf 

±fE;^ T :y ^(c-e) {t1^MMm/5S^ e) ^cC;0-o tcm^it.. -hIBll 6 SP^II 6 <Dm 

2 6. Sf3i^ll2 0. 2 13Z.t*2 2 (DV^-r:rUy?»^<^fS^^K^^-*3V^-r . -hlH^M^mfi 

(a) ±|EM^SrS(x)i:-r^^s-hl2SB^S(x)(D^t±i;^it--y h<^A;^t^'5' VKM-t 

(b) tTffi-r-<#igms(x)f;iov^TA;^^5^Ax ttiiti-^:^i^iUry (D±X(Dm. 

xm^T^mm^mz.n-r^um^m-m^^WT^Bifmmwim^m^m^'Tyzft . 

(c) ±.mmm-r^^rfS^(D±x(Dxtix t^nnhKMft^-r^mtiy^'tri'en 
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2 8. if*^2 7(Df5^^^^{^*5VN-C. 

_bfBM5>.W^5^f ^WttM^S;^ 7^ 5^ ^ (b) «±teF^ms (x) (DT^ti A x 
I s(Ax, ry) = |2X # {xeGF(2)" | (S(x)+S(x+ Ax)) • ry = l}-2"| 

^^fh^f\.M'm(OX-nW:^^^ {Fo. Fi, .... Fu-,} h V m<0\^tiW:^^-^ {Go, 

G,. .... Gv-.} {;i5^SiJb, #^Sim(Fi.Gi)(i=o, ...,u-i:j=o, i,...,v-i)fc:o 
v^TA;^§P5)•*-^Fi (D^A;^ X lc^^£;:-r 2)^01;^ y y5i^^nW(7)|±j;^j$(5^^'^G j 
(j=0. .... v-l) --'j§JR-r S?ll^^3|ti6. ^TCD^^-fiJ^fCF, G) 0;lf «?ft^cD5pi^6^}ii 
0 cDtg^^Is (F, G) ^^46. ^cDm^{c:a':5v^r^#Jife:»j*ti>cti-6B'l4^M-r 5 

2 9. ff^3l2 7X{* 2 8 0|E^|^#:{C^oV^T. ±f5:7°D Af^MJ-. 

(e) _h|5K^S(x)(Dm;bM53'{it^Ay <bi-S^,Ax=0 ^l^< ^T(D^5^1KcD«a 
(Ax, Ay)tCl>Fj-LS(x)+S(x+Ax) = Ay^^-f-x0^^^^i^-ei^*fe^ ^k\.^(Dr> 

(f) iitEM^s(x){cov^T^coA:^x ^^<7)-7>^i^'fiSrx(D[^^;6^.M^thi;^'fit 
S(x) i: ^(7)-^;=^ i5^16r y i: (Dp^^fci^L < T^cf^ X (D^^^*^^>-Cw»^«?^fe^-*l• 
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3 0. m^m2 9(Dmmi^m^^^^x^ ±t?.Ati xcDi^'^y hwc^n t-r=b t. 

(Ax, Ay) (C^L^tL^'ix^^ 

6 s(Ax, Ay) = # {xeGF(2)" | S(x)+S(x+ Ax) = Ay} 

As= max 6s(Ax, Ay) 

^t. ry=o ^m<±X(om(D-^^^mrx, ry) 

Isirx, ry)= I 2X # {xeGF(2)" | x • rx=S(x) • ry}-2" | 
As= max XsiVx, Fy) 
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